time-exchange-gr / oscurrency

Open Source Time Exchange derived from Insoshi
http://time-exchange.gr
Other
9 stars 0 forks source link

make login failure message less informational #78

Open 3point2 opened 12 years ago

3point2 commented 12 years ago

we shouldn't specify if it was the username or password that's incorrect, just say 'there was a problem with your login'. this will prevent people from being able to determine if an account exists or not. note: check password reset submission. there might be an error message for non existent accounts.